Security & Compliance
What we protect, how, and — just as usefully for your review — what we do not have yet.
PearlAudit analyzes public government records. The property data in every dossier is public record, identical for every customer, and holds no personal information about you. The data worth protecting here is your account’s own activity — what your team searched, generated and downloaded, your API keys, and your branding. That is what the controls below are about.
Encryption & transport
All traffic is served over TLS 1.3. The application sends HSTS (two years, including subdomains, preload-eligible), an enforced Content-Security-Policy, X-Frame-Options: DENY plus frame-ancestors ‘none’, nosniff, a strict-origin referrer policy, and a Permissions-Policy that denies camera, microphone, geolocation and topics. These are response headers — you can verify every one of them against the live site before you believe this page.
API keys
Stored hashed
Keys are held as a hash, not as recoverable text. The full key is shown once, at creation, and cannot be retrieved afterwards — if it is lost, the path forward is to revoke and reissue.
Bound to the issuing account
Every key carries its owner and that account’s tier. The tier bounds what the key can reach and how much of it; a per-minute rate budget bounds how fast.
Revocable immediately
Revocation takes effect on the next request. Revoked keys keep their record so the audit trail of what that key did stays intact.
What keys do NOT have
There are no per-endpoint scopes. A key is limited by its tier and its owner, not by a grant list. If your integration needs a read-only or endpoint-restricted credential, say so during scoping — today the honest answer is that we would be building it for you.
Network & administrative surface
The public API is served through an explicit path allowlist at the edge: a route that is not on the list is not reachable from the internet, and administrative endpoints are not on the list. Outbound webhooks are HMAC-signed so your receiver can verify that a delivery came from us and was not altered in transit. The public lead forms are screened before anything is forwarded — a honeypot field, a time-to-submit check, and per-IP throttling.
Audit logging
Every search, dossier generation and download is timestamped and logged against the account that performed it, including through the API. That record is what lets a reviewer reconstruct what was checked on a deal and when.
The limit, stated plainly: attribution today is per account, not per analyst, because an account is currently a single login (see below). A firm sharing one login gets a complete record of what the firm did and no way to tell which analyst did it.
Data isolation & access
The property intelligence is public, read-only government data — the same corpus for every customer, so there is no per-customer property data to leak between accounts. Private account state — search and download history, API keys, watchlists, branding — is access-controlled and scoped to the account that owns it.
Access to production systems is restricted to PearlAudit personnel on a need-to-know basis. We do not grant third-party vendors direct access to your account data.
Retention & deletion
Account information and usage logs are retained for the life of the account and for up to three years after closure, to support billing disputes, legal compliance and audit requirements. You may request deletion of your account and its data at any time; we process deletion requests within 30 days, subject to legal retention obligations. Full detail is in the privacy policy.
Subprocessors
We use a deliberately small number of service providers, each under contract and permitted to use data only to perform services for us: authentication and session management, product analytics, payment processing, and — only when you order a printed briefing — physical mail delivery, which receives the delivery address you supply and nothing else. Municipal and federal data sources receive no personal data at all; we read public records from them.
We publish these by function rather than by vendor name. The named list, with roles and locations, goes to you as part of a security review or under NDA — ask and you will have it.
We do not use Google Analytics, Meta Pixel, or any third-party advertising tracker, and we do not sell your data.
What we do not have yet
No SOC 2 or ISO 27001
We hold neither certification today. We complete vendor security questionnaires and sign a DPA on request, and we would rather tell you this on our own page than have you find it in week three.
No SSO, no per-analyst seats
An account is a single login. There are no organizations, member roles, or SAML/OIDC enterprise connections yet, which is also why audit attribution stops at the account. This is the next thing we are building on the account layer; if a contract depends on it, raise it during scoping and we will give you a date.
No penetration-test report to share
We have no third-party penetration test to hand you. If your process requires one, tell us — it is a scoping conversation, not a brush-off.
No uptime SLA by default
Self-serve plans carry no contractual uptime or support SLA. Availability commitments are negotiated as contract terms on an enterprise agreement; current operational state is on the status page.
Reporting a vulnerability
If you believe you have found a security issue, email help@getpearlaudit.com with enough detail to reproduce it. We will acknowledge you, we will not pursue anyone who reports in good faith and does not exfiltrate data or degrade the service for others, and we will tell you when it is fixed.
Running a vendor review?
Send us your questionnaire and your DPA. We answer them ourselves, and we answer the awkward questions the same way this page does.
Start an enterprise conversation